Vulnerabilities

Fortinet, Ivanti Patch High-Severity Vulnerabilities

Patches released by Fortinet and Ivanti resolve over a dozen vulnerabilities, including high-severity flaws leading to code execution, credential leaks.

Patches released by Fortinet and Ivanti resolve over a dozen vulnerabilities, including high-severity flaws leading to code execution, credential leaks.

Fortinet and Ivanti on Tuesday announced fixes for over a dozen vulnerabilities across their product portfolios, including multiple high-severity flaws.

Ivanti released a Workspace Control (IWC) update to address three high-severity bugs that could lead to credential leaks.

Tracked as CVE-2025-5353, CVE-2025-22463, and CVE-2025-22455, the issues exist because of hardcoded keys in IWC versions 10.19.0.0 and prior, which could allow authenticated attackers to decrypt stored SQL credentials and environment passwords.

“We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure. These vulnerabilities were disclosed through our responsible disclosure program,” the company notes.

Fortinet released 14 patches on Tuesday, to address one high- and 13 medium-severity security defects.

The high-severity issue, tracked as CVE-2025-31104, is described as an OS command injection bug in FortiADC that could allow an authenticated attacker to execute arbitrary code using crafted HTTP requests.

Advertisement. Scroll to continue reading.

The company fixed medium-severity flaws in FortiOS, FortiClientEMS, FortiClient for Windows, FortiPAM, FortiSRA, FortiSASE, FortiPortal, FortiProxy, and FortiWeb.

Attackers could exploit these issues to perform SSRF attacks, inject unauthorized sessions, redirect VPN connections, access unauthorized resources, access SSL-VPN settings, view device information, log into the SSL-VPN portal, elevate privileges, add SSH key files on the system, perform operations on behalf of a targeted user, spoof the identity of a downstream device, and connect from FortiClient via revoked certificates.

Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page.

Related: Chrome, Firefox Updates Resolve High-Severity Memory Bugs

Related: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Related: Critical Vulnerability Patched in SAP NetWeaver

Related: Cometdocs Threatens Legal Action Over Disclosure of Security Issues

Related Content

Endpoint Security

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.

Vulnerabilities

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.

Artificial Intelligence

Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.

Artificial Intelligence

An attacker could self-register, sign in for board-level API access, and import a new company for code execution.

Vulnerabilities

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.

Vulnerabilities

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.

Mobile & Wireless

The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version